{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2f7bd502-4db4-577a-aee9-a95225bf10ca",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-web",
      "version": "5.3.37-tuxcare.10",
      "purl": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9c36d4f0-8929-5291-8c7a-92163edaa839",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac097a43-4f11-5cd2-bd65-7178ab1df082",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edf2a4c2-d8a3-5ddf-abe5-6d707b676471",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:225102a8-ab5f-5553-9380-fa8ee326b95f",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0961c86-c98f-5ebc-a8a9-ee4d1e6af6a2",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c2592ba-9d53-556d-9b16-5c3484abf0ce",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24cf2505-2988-5f5f-83ec-fab2fd715d6a",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76c41101-20d3-53a4-9c92-aeac3a2757e6",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e5babdb-542f-55c0-9bf6-a920563c87a3",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:799fa2c2-39dc-5c40-b481-09f1686aba6d",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d379f08-2825-5726-84d3-82803932bd23",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9867eb5f-837a-5b31-8b1d-5094e3263857",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:320c6ade-d7c6-5ada-a91a-542aa9e6a2c8",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3359fffb-8ef0-569d-b056-ed2996ea4076",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44753afc-d005-59e3-9b9b-4279bef34eec",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d339ec8-43be-5cba-ba83-832dee355897",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0644292-d42a-5e53-96e7-579be93e9f53",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d444c46e-9804-5bda-992e-1c93ffb2b44a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d399eb7-06df-5f7b-ae62-202c02ca966a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-web. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82121e36-6d39-5253-917e-96cbce5f8afa",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10f7bf59-d1a7-5734-9c98-89be77a3007f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2c4688a-54bf-56a3-ad8d-431107310cde",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:015f7eba-691e-53e5-a660-ec795006299f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dd5f114-f42d-5f33-956a-1da1f90a0119",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5807d37-f570-5fbe-a5ae-bf6138670f8d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98b5b78c-3ff4-585a-82bd-8f7035496aa7",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18a2fcdf-56f4-5165-849e-cffd11bf3da3",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:997e7ede-1c92-598b-97aa-ca02f8d60612",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-web. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db8b80f1-2bdb-574d-9a20-366b49482c47",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86314fa8-4778-564f-b6d4-466bf4d484e3",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53f98af2-5071-5b73-8612-2673df371950",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76e0c213-0cb2-53af-81d4-ed9d5446f5d4",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c374bb8-2ce9-5451-bfab-ff31aff0204e",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-web. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97888a52-4f53-5cc0-94b5-a7e5687acc94",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f271ed6-5401-5b46-a12a-29d9549914a8",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fd5bc92-560d-53be-9a6e-3f406e247851",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da8af7d2-b0f5-59bf-8c6c-c79f68c16776",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f16c130d-ddc8-52a2-8613-23f8b0d7ced6",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b5fca40-3ed6-52de-afa1-89f6a0a49b01",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:275b68fb-6677-5195-847f-08f4a12bb1e6",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1b3f530-f2a8-51b8-bc45-e8af882885a8",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5cb45de-d42f-510e-82cd-396ef0b8a0ca",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:653cd76d-819f-5293-89ea-c3eb37da3837",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ffb6b02-efde-5dc2-85e1-13ad4da0ed81",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f5e06b3-6371-59c4-a968-1be25e7a34f6",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9452ce8a-194c-5aaa-b917-5973accd46b7",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29d12aed-9a08-5676-9d2d-2af56784d355",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.37-tuxcare.10 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.10"
    }
  ]
}